2026 CVE Vulnerabilities

64,705 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-19599CRITICAL9.9ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability...
CVE-2026-86350CRITICAL9.1Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response smuggling') vulnerability in Apache Tomcat caused...
CVE-2026-86248CRITICAL9.8CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apac...
CVE-2026-76183CRITICAL9.8Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocke...
CVE-2026-82331CRITICAL9.8Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildS...
CVE-2026-82843CRITICAL9The WP OAuth Server ( Login with WordPress ) WordPress plugin before 6.4.0 does not bind the OpenID Connect identity ass...
CVE-2026-75799CRITICAL9The YAHMAN Add-ons WordPress plugin before 0.9.31 does not validate the type of the remote files it caches in a publicly...
CVE-2026-96257CRITICAL10A flaw has been found in Fast FAC1203R Gigabit Edition 2.0.4. Affected by this issue is the function copy_msg_element of...
CVE-2026-18169CRITICAL9.9IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to obtain sensi...
CVE-2026-18163CRITICAL9.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due...
CVE-2026-18162CRITICAL9.8IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to execute arbitrary code due...
CVE-2026-19202CRITICAL9.1A caching flaw in the toolbox-core package of the mcp-toolbox-sdk-python SDK causes the same Google ID token to be cache...
CVE-2026-17645CRITICAL9.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote authenticated attacker to gain elevate...
CVE-2026-17635CRITICAL9.1IBM Financial Transaction Manager (FTM) for RedHat OpenShift could allow a remote attacker to perform unauthorized actio...
CVE-2026-17472CRITICAL9.6IBM Concert 1.0.0 through 3.0.0 could allow a remote authenticated attacker to access or modify unauthorized resources d...
CVE-2026-16346CRITICAL9.9IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands du...
CVE-2026-77987CRITICAL9.3A server-side request forgery (SSRF) vulnerability was identified in the notebook viewer of GitHub Enterprise Server. Th...
CVE-2026-89282CRITICAL9.1The Apache Lounge Windows distribution of Apache HTTP Server build contains an insecure installation directory permissio...
CVE-2026-88624CRITICAL9.1Missing path validation in the Worktree.remove component of openCode v1.18.26 allows attackers to execute arbitrary recu...
CVE-2026-87121CRITICAL9.8lwIP TCP/IP Stack MQTT is vulnerable to an out-of-bounds write, which may allow an attacker to gain full code execution ...
CVE-2026-76709CRITICAL9.8A vulnerability exists in the internal administrative component of Analytics and Location Engine (ALE). Successful explo...
CVE-2026-76708CRITICAL9.8A vulnerability exists in the Analytics and Location Engine (ALE) where the application and underlying operating system ...
CVE-2026-47116CRITICAL9.8LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where the root and guest account passwords are stor...
CVE-2026-28324CRITICAL9.8SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability ...
CVE-2026-91130CRITICAL9.3Home Assistant is open source home automation software focused on local control and privacy. Prior to 2026.7.0, the Stat...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now